CVE-2018-6497
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
16/06/2018
Last modified:
07/11/2023
Description
Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Server version DDM Content Pack V 10.20, 10.21, 10.22, 10.22 CUP7, 10.30, 10.31, 10.32, 10.33, 10.33 CUP2, 11.0 and CMS Server version 2018.05 BACKGROUND which could allow for remote unsafe deserialization and cross-site request forgery (CSRF).
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:microfocus:cms_server:2018.05:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microfocus:universal_cmbd_server:*:*:*:*:*:*:*:* | 10.20 (including) | 11.0 (including) |
To consult the complete list of CPE names with products and versions, see this page



